Content

DAT Readme

Download the latest anti virus definitions for McAfee® VirusScan®. Ensure your McAfee® product contains the most up-to-date detection and prevention.
http://www.mcafee.com/apps/downloads/security_updates/dat.asp

DAT Version 4367
DAT Release Date 06/16/2004
Threats Detected 92006
New Detections 95
Enhanced Detections 245

Enhanced detections are those that have been modified for this release. Detections are enhanced to cover new variants, optimize performance, and correct incorrect identifications.

Noteworthy threats are those that had an Avert risk assessment of Low-Profiled, Medium, Medium-On-Watch, High, or High-Outbreak at the time of DAT release.

Noteworthy Threats:

Name Corporate Risk Assessment Home Risk Assessment
JS/Exploit-DialogArg.b Low-Profiled Low-Profiled
W32/Sober.h Low-Profiled Low-Profiled

New Detections:

Program (9)
   (1)
    Tool/mac10
  Dialer (3)
    Dialer-205
    Dialer-RAS.df
    Dialer-RAS.de
  Generic (1)
    Dialer-RAS.df.gen
  Joke (1)
    Joke-Flipped.b
  Malware Tool (1)
    Htool/Remcruft
  Spyware (2)
    Spyware-NetReplicat
    Spyware-CatchaSneak
Trojan (61)
   (2)
    Tool/QQAtack
    QHosts-1!hosts
  Application extension (2)
    Downloader-LG.dll
    BackDoor-CFO.dll
  Client (1)
    BackDoor-ASB.cli
  Demonstration (1)
    Exploit-HCPRemoteExe.demo
  Downloader (9)
    Downloader-LJ
    Downloader-LI
    Downloader-LH
    Downloader-LG
    Downloader-LF
    Downloader-LE
    Downloader-LD
    Dialer-205.dldr
    StartPage-BT.dldr
  Dropper (5)
    Downloader-LJ.dr
    PWS-Iyus.dr
    BackDoor-AZG.dr
    BackDoor-ASB.dr
    Spy-Tofger.dr
  E-mail (1)
    W32/Sober.h
  Exploit (4)
    Exploit-SMBAdde
    JS/Exploit-DialogArg.b
    Exploit-MhtRedir!chm
    JS/Exploit-DialogArg.a
  Heuristic (1)
    New BackDoor6c
  Malware Tool (2)
    Kit-Asank
    Kit-ZipInfect
  Password Stealer (1)
    PWS-Etry
  Remote Access (10)
    BackDoor-CFV
    BackDoor-CFU
    BackDoor-CFT
    BackDoor-CFS
    BackDoor-CFR
    BackDoor-CFQ
    BackDoor-CFP
    BackDoor-CFO
    BackDoor-CFN
    JS/BackDoor-BCB
  Script (9)
    VBS/Asank
    Bat/qz129
    Bat/klw8
    Bat/avk30
    VBS/Thoza
    VBS/Naba
    Bat/Conic
    Bat/avk31
    Del-454
  StartPage (5)
    StartPage-DU
    StartPage-DT
    StartPage-DS
    StartPage-DR
    StartPage-DQ
  Vulnerability (1)
    JS/Stealus
  Win32 (7)
    KillYah
    HaScreen
    CeCinta
    SonOfArt
    Generic QHosts.a
    Parpa
    MSNPeriod
Virus (23)
   (1)
    Cascade.1701.bo
  Damaged (2)
    Linux/Debilove.dam
    W32/Zafi.b.dam
  Damaged Worm (1)
    W32/Sdbot.worm.dam
  Email (3)
    W32/Zafi.a@MM
    W32/Tubty@MM
    W32/Sober.g@MM!zip
  Email Generic (1)
    W32/Zafi.gen.b@MM
  Generic (1)
    W32/Zafi.gen
  Generic Worm (1)
    W32/Nodab.worm.gen
  Internet Relay Chat Worm (2)
    W32/Scanbot.worm!irc
    W32/Plesa.worm!irc
  Linux (1)
    Linux/Debilove.10714
  Script (2)
    VBS/Mill
    VBS/Linbog
  VbScript (1)
    VBS/Pub
  Win32 (3)
    W32/Polybot.bj
    W32/Polybot.bi
    W32/Mydoom.k.eml!exe
  Worm (4)
    Symbian/Cabir
    Unix/Siback.worm
    W32/Robot.worm
    W32/Nives.worm

Enhanced Detections:

Internet Worm (1)
  Win32 (1)
    New Worm
Program (23)
   (1)
    Tool/W311
  - (2)
    Proxy-Daemonize
    RemoteProcessLaunch
  Adware (8)
    IPSentry
    Adware-TopMoxie
    Adware-HotBar
    Adware-BetterInet
    Adware-PurityScan
    Adware-Lop
    Adware-SearchV
    Adware-JimHelp
  Application extension (1)
    Dialer-Generic.dll
  Dialer (1)
    Dialer-Generic.b
  Downloader (1)
    Adware-Rfwnad.dldr
  Exploit (1)
    Exploit-WebDAV
  Generic (1)
    Keylog-Perfect.gen
  Malware Tool (2)
    VTool/fake
    HTool/kker
  Remote Access (1)
    ServU-Daemon
  Spyware (1)
    Keylog-Perfect
  Win32 (3)
    IMIServer.download
    AdwareDropper-B
    PSKill
Trojan (84)
   (3)
    Generic PWS.b
    Generic BackDoor.d
    Generic Keylogger
  Application extension (3)
    BackDoor-AXJ.dll
    Downloader-DA.dll
    PWS-LegMir.dll
  Configurator (1)
    MultiDropper-FQ.cfg
  Demonstration (1)
    JS/Exploit-DialogArg.demo
  DOS (1)
    Unsafe COM
  Downloader (5)
    Downloader-DS
    PWS-LegMir.dldr
    Downloader-LB
    Downloader-KZ
    Downloader-KT
  Dropper (5)
    MultiDropper-GK
    VBS/Inor
    PWS-Bancban.dr
    MultiDropper-FQ
    Downloader-KP
  Exploit (4)
    VBS/Psyme
    Exploit-IFrame
    JS/Exploit-DialogArg
    Exploit-MhtRedir.gen
  Generic (6)
    Exploit-DcomRpc.gen
    VBS/IEstart.gen.f
    JS/IEstart.gen.d
    PWS-Bancban.gen.b
    BackDoor-ASB.gen
    Spy-Tofger.gen.b
  Heuristic (1)
    New BackDoor6b
  HTML (2)
    HTML/Suar
    JS/Winbomb
  Internet Relay Chat (3)
    IRC/Flood.c
    IRC-Scanbot
    IRC-Rabagi
  Java Applet (1)
    JV/Shinwow
  JavaScript (1)
    JS/CardStealer
  Macro (1)
    A97M/AcceV
  Malware Tool (1)
    Kit-Sevenc
  Password (9)
    PWS-Moneykeeper
    PWS-Bancos
    PWS-QQPass
    PWS-Msnfake
    PWS-LDPinch
    HTML/Ebscam
    PWS-WebMoney.gen
    Keylog-Lodis
    PWS-GWGhost
  Password Stealer (1)
    PWS-Harvester
  Remote Access (9)
    BackDoor-AXJ
    BackDoor-ASB
    BackDoor-ARR
    BackDoor-AJU
    BackDoor-BCB
    BackDoor-ANC
    BackDoor-TC
    BackDoor-CFM
    BackDoor-BR
  Script (9)
    Univ.script/99b
    Univ.script/99a
    VBS/SevenC
    JS/AdClicker-AG
    New CardStealer
    VBS/Delfile
    VBS/ShareEnable
    JS/Seeker.v
    Bat/Sepy
  Server (1)
    BackDoor-ARR.svr
  StartPage (3)
    StartPage-DK
    StartPage-DC
    StartPage-CZ
  Win32 (13)
    Generic VB
    Generic Downloader.a
    Generic BackDoor.b
    HackerDefender
    Keylog-Stawin
    Generic BackDoor.f
    IRC-Sdbot
    Generic MSVC
    Generic Del
    Generic VB.c
    LogOff
    DDoS-Boxed
    AIM-Clone
Virus (137)
   (73)
    Cascade.1701.bm
    Cascade.1701.bk
    Cascade.1701.bj
    Cascade.1701.bi
    Cascade.1701.bh
    Cascade.1701.bf
    Cascade.1701.be
    Cascade.1701.bb
    Cascade.1701.az
    Cascade.1701.ay
    Cascade.1701.Yap.i
    Cascade.1701.aw
    Cascade.1701.av
    Cascade.1701.au
    Cascade.1701.ar
    Cascade.1701.aq
    Cascade.1701.ap
    Cascade.1701.Yap.h
    Cascade.1701.ao
    Cascade.1701.an
    Cascade.1701.Yap.g
    Cascade.1701.am
    Cascade.1701.al
    Cascade.1701.ak
    Cascade.1701.aj
    Cascade.1701.Yap.f
    Cascade.1701.Yap.e
    Cascade.1701.ai
    Cascade.1701.ah
    Cascade.1701.Yap.d
    Cascade.1701.z
    Cascade.1701.y
    Cascade.1701.Yap.c
    Cascade.1701.Yap.b
    Cascade.1701.q
    Cascade.1701.bd
    Cascade.1701.bc
    Cascade.1701.ba
    Cascade.1701.at
    Cascade.1701.ag
    Cascade.1701.af
    Cascade.1701.ae
    Cascade.1701.ad
    Cascade.1701.ac
    Cascade.1701.ab
    Cascade.1701.aa
    Cascade.1701.x
    Cascade.1701.w
    Cascade.1701.v
    Cascade.1701.s
    Cascade.1701.p
    Cascade.1701.n
    Cascade.1701.m
    Cascade.1701.j
    Cascade.1701.i
    Cascade.1701.h
    Cascade.1701.g
    Cascade.1701.e
    Cascade.1701.Yap.a
    Cascade.1701.d
    Cascade.1701.c
    Cascade.1701.b
    Cascade.1701
    Cascade.1701.as
    Cascade.1701.bl
    Cascade.1701.bg
    Cascade.1701.u
    Cascade.1701.t
    Cascade.1701.r
    Cascade.1701.o
    Cascade.1701.l
    Cascade.1701.k
    Cascade.1701.f
  Application extension (1)
    W32/Demig.dll
  Application extension Generi (1)
    W32/Bagle.dll.gen
  Damaged (1)
    Anti-Pascal.dam
  Damaged Worm (2)
    W32/Spybot.worm.dam
    W32/Gaobot.worm.dam
  Dropper (3)
    Univ/j.dr
    Cascade.1701.q.dr
    Univ.topsy.dr
  E-mail (4)
    W32/Mydoom.b@MM
    W32/Mydoom.h@MM
    W32/Mydoom.e@MM
    W32/Mydoom.k@MM
  E-mail worm (4)
    W32/Mydoom.g@MM
    W32/Mydoom.f@MM
    W32/Bagle.z@MM
    W32/Bagle.aa@MM
  Email (7)
    W32/Mydoom.i@MM
    W32/Mydoom.a@MM
    W32/Mydoom.j@MM
    W32/Sober.d@MM!zip
    W32/Sober.e@MM!zip
    W32/Mydoom.l@MM
    W32/Zafi.b@MM
  File Infector (2)
    Generic
    Cascade.1701.A
  Generic (1)
    Bat/BWG.gen
  Generic Worm (10)
    W32/Gaobot.worm.gen.g
    W32/Gaobot.worm.gen.f
    W32/Gaobot.worm.gen.e
    W32/Gaobot.worm.gen.l
    W32/Spybot.worm.gen.g
    W32/Sdbot.worm.gen.o
    W32/Sdbot.worm.gen.i
    W32/Randbot.worm.gen.d
    W32/Randbot.worm.gen.b
    W32/Gaobot.worm.gen.h
  HTML document (1)
    Cybesh.html
  Intended (1)
    VBS/Redlof.intd
  Internet Relay Chat (1)
    W32/Diam!irc
  Internet Worm (3)
    W32/Netspree.worm
    W32/Gaobot.worm.ali
    W32/Gaobot.worm.gen.q
  Macro (4)
    X97M/Laroux
    W97M/Coke.22231.a
    X97M/Toraja
    W97M/Matem
  Open Share Worm (1)
    W32/Dedler.worm.gen
  Script (3)
    Bat/flm
    JS/Malex
    VBS/Uxor
  Universal (3)
    Univ/j
    Univ.topsy
    Univ.prepend
  VbScript (1)
    New Script
  Win32 (6)
    New Win32.g1
    New Win32
    W32/Shansui
    W32/Mydoom.a.eml!exe
    W32/Mydoom.g.eml!exe
    W32/Bagle.ab!vbs
  Win9x (1)
    W95/Coke.22231
  Worm (3)
    W32/Fesber.worm
    W32/Dedler.worm
    VBS/Pica.worm